>> rPath Security Update Fixes Evolution-data-server Information Disclosure Weakness
Title : rPath Security Update Fixes Evolution-data-server Information Disclosure Weakness VUPEN ID : VUPEN/ADV-2007-2201 CVE ID : CVE-2007-1558 - CVE-2007-3257
Rated as : Low Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-06-15
Technical Description
A weakness has been identified in rPath Linux, which could be exploited by remote attackers to gain knowledge of sensitive information. This issue is caused by an error in the APOP protocol within evolution-data-server that fails to properly prevent MD5 collisions, which could be exploited via man-in-the-middle attacks and specially crafted message-IDs to potentially disclose the first three characters of passwords.